← Vulnerability feed

Vulnerability record · CVE-2022-32174 · published 11 October 2022

CVE-2022-32174: Gogs stored XSS in gogs.js leads to account takeover

Gogs · Gogs

Gogs versions v0.6.5 through v0.12.10 contain a stored cross-site scripting flaw in the client-side code at public/js/gogs.js. Because the injected script persists and executes in other users' sessions, it can be used to take over accounts. The record gives no further detail on the exact injection point or payload.

9.0 CVSS 3.1 Critical EPSS 58% · top 0.9% CWE-79 · Cross-site scripting
9.0CVSS 3.1 base score
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCritical CVSS 9.0 stored XSS with account takeover impact and very high EPSS, though it requires an authenticated attacker and victim interaction and is not in KEV.

What it is

Gogs versions v0.6.5 through v0.12.10 contain a stored cross-site scripting flaw in the client-side code at public/js/gogs.js. Because the injected script persists and executes in other users' sessions, it can be used to take over accounts. The record gives no further detail on the exact injection point or payload.

Impact

An attacker who can plant the stored payload can execute script in a victim's browser session and take over that account, including any repository or administrative access the victim holds.

Attack surface

Reachable over the network through the Gogs web interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs an authenticated account and the victim must view the affected content.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.58021 (99th percentile) and two references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Gogs past v0.12.10 to a release that fixes the stored XSS in public/js/gogs.js.
  • If immediate upgrade is not possible, restrict who can create or edit the content that carries the stored payload and review existing stored content for injected scripts.
  • Deploy a Content-Security-Policy that blocks inline and untrusted script execution in the Gogs web UI.
  • Enable HttpOnly and Secure flags on session cookies to limit session theft if script does execute.
  • Audit accounts for unexpected session or credential changes that could indicate prior exploitation.

Detection

  • Search web and proxy logs for requests to Gogs pages containing script tags or encoded script payloads in user-controlled fields.
  • Monitor for anomalous authenticated actions such as email, password or SSH key changes shortly after a user views stored content.
  • Review stored repository, issue, comment and profile content for inline script or event-handler attributes.
  • Alert on Gogs sessions originating from new user agents or IP addresses inconsistent with the account's normal activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-32174 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-8110Gogs PutContents API symlink handling allows remote code executionThe PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (C…KEVEPSS 85%analysed9.9CVE-2024-39930Gogs argument injection vulnerabilityThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated atta…EPSS 7.7%9.9CVE-2024-39931Gogs internal file deletion via path handling flawGogs through 0.13.0 allows deletion of internal files. The flaw is a path handling issue (CWE-552) that lets a user with a valid account remove files…EPSS 53%analysed9.9CVE-2024-39932Gogs code injection vulnerabilityGogs through 0.13.0 allows argument injection during the previewing of changes.EPSS 17%9.8CVE-2024-56731Gogs vulnerabilityGogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve rem…EPSS 1.2%9.8CVE-2022-1884Gogs os command injection vulnerabilityA remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…EPSS 1.8%9.8CVE-2022-2024Gogs OS command injection before 0.12.11Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critic…EPSS 98%analysed9.8CVE-2022-1986Gogs os command injection vulnerabilityOS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2022-32174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.